Advance
AI Governance Advisory
Governance that keeps AI adoption accountable, compliant and trusted as it scales. Framework, policy, risk and compliance alignment, informed by ISO/IEC 42001 and written for the Mauritian and regional regulatory environment, not lifted from a multinational template.
The problem governance solves
In most organisations AI governance arrives after the incident: a decision nobody can explain, customer data pasted into a public tool, a vendor model making calls nobody reviewed. The policy is then written in a hurry, by people who were not in the room when the systems were chosen.
Mauritius now has a National AI Strategy built on FAIR principles, fairness, accountability, inclusiveness and responsibility, and a Data Protection Act that already applies to most of what AI systems do with personal data. Organisations that adopt AI without governance are not operating in a grey area. They are operating without a map of obligations they already have.
Who this is for
- Boards and audit committees that want AI risk treated with the same discipline as financial or operational risk
- Public-sector and parastatal bodies aligning to the National AI Strategy and its FAIR guidelines
- Regulated organisations in financial services, healthcare and telecoms deploying AI in decisions that affect customers
- SMEs scaling from one AI use case to several, and discovering that informal oversight no longer holds
What Consultaix does
Consultaix designs governance that fits the organisation's actual AI footprint: what is in use, who owns it, what decisions it touches, and what could go wrong. The framework covers accountability, risk assessment, data handling, human oversight, vendor and model review, and the cadence at which all of it is revisited.
The work is informed by ISO/IEC 42001, the international standard for AI management systems, which Faaleh M. Sookye is certified to implement. Alignment with the standard is designed in from the start for organisations that may later seek certification, without imposing its full weight on those that will not.
How the work runs
- AI inventory and risk mapEvery AI system in use or planned, including those arriving through vendors, mapped to the decisions it affects and the data it touches.
- Framework designAccountability, oversight, risk classification and review cadence, sized to the organisation and aligned to the FAIR principles and the Data Protection Act.
- Policy and documentationAn AI policy people can follow, with the register, assessment templates and review records that make it operational.
- EmbeddingBriefings for the board and the people who own the systems, and a first review cycle run with Consultaix in the room.
ISO/IEC 42001 in Mauritius
ISO/IEC 42001:2023 is the international standard for an AI management system: the policies, roles, risk assessments and controls an organisation uses to govern AI responsibly. Certification is assessed by accredited bodies; Consultaix does not certify. What Consultaix does is design the governance framework so that it already follows the structure of the standard, which shortens the path for organisations that later seek certification and gives those that do not a recognised reference point for their board and regulators. Faaleh M. Sookye is a Certified ISO/IEC 42001:2023 Implementer.
What Mauritian organisations are already subject to
- The FAIR Guidelines under the National AI Strategy 2025 to 2029: fairness, accountability, inclusiveness and responsibility across the AI lifecycle. Non-binding, addressed to public and private organisations alike, with a stated path toward procurement standards and, where justified by risk, legislation.
- The FSC Guidance Note on the Responsible Use of AI in Financial Services, which applies to insurers, wealth managers and other non-bank financial licensees.
- The Data Protection Act 2017, including its rules on automated individual decision-making and data protection impact assessments, which already cover most of what AI systems do with personal data.
A Consultaix governance framework maps the organisation's AI footprint to each of these, so obligations are met once, in one set of documents, rather than rediscovered instrument by instrument.
What you have at the end
A governance framework and AI policy in force, with named accountability. A risk register covering every AI system in use. Documentation that would stand up to a regulator, an auditor or an ISO/IEC 42001 assessor. A review cadence the organisation can run without us.
Governance is the Advance stage of the Consultaix sequence. It usually follows an assessment, where the governance dimension is scored first, but it can be engaged on its own where AI is already in use.